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• More than 1,800 flights within, into, or out of the United States were cancelled February 9 
due to a massive snow storm that swept across the Northeast region of the country. - USA 
Today (See item 10 ) 

• A semi-truck that overturned on U.S. 40 in Daniels Canyon in Utah February 6 spilled 
12,000 gallons of crude oil and ignited a large blaze that prompted the closure of the 
highway in both directions for nearly 12 hours. - KSL 5 Salt Lake City (See item 11 ) 

• California health officials reported that 107 cases of measles were confirmed in the State 
February 9, with 39 cases linked to a December 2014 outbreak that began in Disneyland. - 
Reuters (See item 21 ) 

• A researcher released 10 million usemame/password combinations that he collected over 
the years on the Web in an effort to advance research and make authentication more secure. 
- Securityweek (See item 29) 
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Energy Sector 



1. February 9, Securityweek - (National) API vulnerability exposed accounts of 

Delmarva Power customers. Delmarva Power, a subsidiary of Pepco Holdings, issued 
a patch in January addressing a vulnerability in its Android app after a researcher 
discovered the application programming interface (API) is plagued by Insecure Direct 
Object Reference (IDOR), which could have allowed an attacker to hijack customer’s 
online accounts by resetting user’s passwords and gaining control over their accounts. 
Source: http://www.securitvweek.com/api-vulnerabilitv-exposed-accounts-delmarva- 
power-customers 

[ Return to top ] 

Chemical Industry Sector 

Nothing to report 
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Nuclear Reactors, Materials, and Waste Sector 

2. February 9, Associated Press - (Vermont) Radioactive isotope found in well at 
Vermont Yankee. Vennont’s health department reported February 9 that ground water 
at the shuttered Yankee Nuclear Power Station in Vernon sampled in August 2014 was 
verified January 29 to containing low levels of radioactive isotope strontium-90. 
Authorities stated that the water is unavailable for consumption and poses no 
immediate health risk. 

Source: http://www.wggb.com/2015/02/09/radioactive-isotope-found-in-well-at- 
vermont- yankee/ 

[ Return to top ] 

Critical Manufacturing Sector 

3. February 10, ABC News - (National) Samsung clarifies privacy policy: What your 
Smart TV can really hear. Samsung announced that users can manually disable a 
voice recognition function on its voice-recognizing smart televisions that could 
potentially collect interactive voice commands and send them to the third-party service, 
Nuance Communications. A previous policy warned consumers to be aware of spoken 
words that could be included among data captured by the television’s microphone and 
transmitted to a third party. 

Source: http://abcnews.go.com/Technologv/samsung-clarifies-privacv-policy-smart-tv- 
hear/story?id=28861189 
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Defense Industrial Base Sector 



Nothing to report 
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Financial Services Sector 

4. February 9, Bergen County Record - (National) Waldwick police seize 125 credit 
cards from Walgreens customers. Three individuals were arrested by police at a 
Waldwick Walgreens February 7 when they were caught with more than 125 stolen 
credit cards allegedly taken from all over the U.S. The suspects were caught while they 
were purchasing a gift card and police found additional gift cards on them while they 
were arrested. 

Source: http://www.northiersev.com/news/waldwick-police-seize-125-credit-cards- 
from-walgreens-customers- 1 . 1 267484 

5. February 9, Reuters - (New York) New York plans cybersecurity reviews of 
insurers after breach. New York’s Financial Services Department announced plans 
February 9 to increase State insurers preparedness through regular cyber-security 
reviews and enhanced regulations in the wake of February’s Anthem Inc., breach that 
affected up to 80 million customers. 

Source: http://www.reuters.com/article/2015/02/09/us-anthem-cybersecuritv-new-vork- 
idUSKBN0LDlR6201 50209 
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Transportation Systems Sector 

6. February 10, KNTV 11 San Jose - (California) Mudslide closes Highway 9 in Santa 
Cruz County. Highway 9 south of Highway 35 in Santa Cruz County was closed in 
both directions for approximately 14 hours February 9 due to a mudslide that blocked 
the roadway with debris. 

Source: http://www.nbcbavarea.com/news/local/Mudslide-Closes-Highway-9-in-Santa- 
Cruz-County-29 1305281 .html 

7. February 10, WCAU 10 Philadelphia; Associated Press - (New Jersey) 1 dies as 40 
cars, trucks pile up along New Jersey Turnpike. A series of multi-vehicle crashes on 
the New Jersey Turnpike in Middlesex County February 9 closed southbound lanes for 
at least 6 hours while crews cleared the scene. Police reported February 10 that icy road 
conditions are believed to have played a role in the accidents that involved 40 vehicles 
and left at least 1 person dead and dozens more injured. 

Source: http://www.nbcphiladelphia.com/news/local/At-Least-l-Hurt-in-15-Car-Crash- 
on-NJ-Turnpike-291347061.html 

8. February 10, Associated Press - (Texas) US Airways flight makes emergency 
landing at Houston airport. A U.S. Airways flight that departed Philadelphia 
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International Airport made an emergency landing at George Bush Intercontinental 
Airport in Houston February 9 due to a problem with the plane’s nose gear. The plane 
which carried at least 52 passengers and 4 crew members landed safely without its nose 
gear being deployed and 1 passenger was taken to a local hospital with non-life- 
threatening injuries. 

Source: http://www.heraldstandard.com/united states ap/us-airways-flight-makes- 
emergency-landing-at-houston-airport/article 33b58abc-5b5b-5542-a222- 
Iec898b75a09.html 



9. February 9, Associated Press - (California) Landslide closes part of old Highway 40 
near Donner. The California Highway Patrol announced February 9 that a 3-mile 
stretch of old Highway 40 between Truckee and the Sugar - Bowl ski resort will remain 
closed for several days due to a landslide that occurred February 6. Officials made 
plans to use large construction equipment to help clear the roadway of large granite 
boulders. 

Source: http://www.kolotv.com/home/headlines/Landslide-Closes-Part-of-01d- 
Highway-40-Near-Donner-291301561.html 

10. February 9, USA Today - (National) Airlines cancel flights as another snowstorm 
hits northeast. More than 1,800 flights within, into, or out of the United States were 
canceled February 9 due to a massive snow storm that swept across the Northeast 
region of the country. Airports in the New York City area reported significant delays 
for inbound flights, including average delays of almost 7 hours for flights headed to 
LaGuardia Airport. 

Source: http://www.usatodav.com/storv/todavintheskv/2015/02/09/northeast-snow- 
flight-cancellations/231 1 1291/ 

11. February 7, KSL 5 Salt Lake City - (Utah) Daniels Canyon opens after oil tanker 
crash, fire. A semi-truck that overturned on U.S. 40 in Daniels Canyon February 6 
spilled 12,000 gallons of crude oil and ignited a large blaze that prompted the closure 
of the highway in both directions for nearly 12 hours. One lane of the highway was 
scheduled to remain open February 7-8 while crews responded to road damage and 
environmental cleanup, and a second lane in the opposite direction reopened ahead of 
schedule February 7. 

Source: http://www.ksl.com/?nid=148&sid=33385876 
For another story, see item 17 
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Food and Agriculture Sector 

12. February 10, Associated Press - (Michigan) 50,000 turkeys die at Michigan farm; 
feed cited. The U.S. Food and Drug Administration and the U.S. Department of 
Agriculture are investigating the August 2014 death of about 50,000 turkeys at 5 farms 
owned by Sietsema Farms of Allendale and are working to determine how oil intended 
for industrial use was shipped to the farms as a feed additive. Officials reported at a 
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January meeting of the Michigan Commission of Agriculture and Rural Development 
that steps were taken to prevent health risks to customers, while the company reported a 
loss of about $1 million. 

Source: http://www.freep.com/story/news/local/michigan/2015/02/10/turkev-deaths- 
michigan-feed/23 162733/ 

13. February 10, KHOU 11 Houston; Associated Press - (Texas) Giant African snails 
seized at IAH Airport. U.S. Customs and Border Protection (CBP) inspectors 
intercepted six live giant African snails intended for human consumption at George 
Bush International Airport February 2 after a passenger from Nigeria declared the 
animals during a CBP inspection. No charges were filed because there is no penalty 
when international travelers make a truthful declaration. 

Source: http://www.khou.com/storv/news/local/animals/2015/02/10/giant-african- 
snails-seized-at-iah-airport/23 161541/ 

14. February 9, U.S. Food and Drug Administration - (National) National Choice Bakery 
issues allergy alert on undeclared peanuts & tree nuts in bagels. The U.S. Food and 
Drug Administration reported February 9 that National Choice Bakery issued a recall 
for bagels sold under several brand names after it was discovered that undeclared 
peanuts and almonds were found in gluten from a single supplier used in the affected 
products. 

Source: http://www.fda.gov/Safety/Recalls/ucm433566.htm 

15. February 9, U.S. Food and Drug Administration - (National) Whole Foods Market 
recalls items prepared with supplier-provided ground cumin spice due to possible 
health risk. The U.S. Food and Drug Administration announced February 9 that Whole 
Foods Market recalled several items prepared with a ground cumin spice ingredient 
after a supplier notified the company that the spice may contain undeclared peanut 
protein. The affected products include items such as prepared salads, seasoned meat 
items, tacos, and other seasoned items that were sold from January 14 through February 
6 at Whole Foods Market stores in several States. 

Source: http://www.fda.gov/Safety/Recalls/ucm433572.htm 

16. February 9, U.S. Environmental Protection Agency - (Washington) National 
wholesale grocery distributor, Supervalu Holdings, Inc., agrees to settle EPA 
violations and protect local waters from stormwater pollution. Supervalu Holdings, 
Inc., a Minnesota-based national wholesale grocery distributor, entered an agreement 
with the U.S. Environmental Protection Agency February 9 to resolve charges of 
federal stormwater pollution violations that threatened the Puget Sound following an 
inspection at 3 Supervalu facilities in Washington. Supervalu agreed to pay $120,000 in 
penalties. 

Source: 

http://vosemite.epa.gov/opa/admpress.nsf/21b8983ffa5d0e4685257dd4006b85e2/02cf7 

9ae31ce875485257de7007cdd2e 
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17. February 9, U.S. Department of Labor - (Ohio) Reynolds Nationwide exposes 



workers to dangerous fumes in food transport tankers at London, Ohio, facility. 

The Occupational Safety and Health Administration cited Reynolds Nationwide for 6 
serious and 2 willful violations and issued $179,000 in fines following an August 2014 
investigation of the freight-handling company’s tank-cleaning facility in London, Ohio. 
Inspectors found that employees risked potentially lethal suffocation caused by 
dangerous fumes since the company failed to properly ventilate the air and test the 
atmosphere. 

Source: 

https://www.osha.gov/pls/oshaweb/owadisp.show document?p table=NEWS RELEA 
SES&p id=27357 
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Water and Wastewater Systems Sector 

18. February 10, KRCR 7 Redding - (California) Malfunctioning chlorine alarm forces 
evacuation. The Fishermen Point Water Treatment Plant in the City of Shasta Lake 
was evacuated for several hours February 10 due to reports of a chlorine leak alarm 
going off. An investigation by California Department of Forestry and Fire Protection 
crews determined there was no leak and that the alarm malfunctioned. 

Source: http://www.krcrtv.com/news/local/reported-chlorine-leak-forces- 
evacuation/31 190268 



19. February 9, WWBT 12 Richmond - (Virginia) DEE: Chemical leak at Chesterfield 
Jail didn’t contaminate waterway. The Chesterfield Department of Environmental 
Engineering reported February 9 that an environmental cleanup company retrieved 
more than 20,000 gallons of water from a waterway that was contaminated by a leak 
from an HVAC unit at the Chesterfield Jail in Virginia. The chemical found in the 
waterway was a non-toxic combination of leak-detection dye, rust inhibitor, and 
propylene glycol and has no harmful environmental effects or increased toxicity. 
Source: http://www.nbcl2.com/story/28063358/dee-antifreeze-leak-at-chesterfield-iail- 
didnt-contaminate-waterway 

20. February 9, Las Cruces Sun-News - (New Mexico) Water main leak forces 4-hour 
water shutoff Monday in Hatch. Up to 1,600 homes and businesses in Hatch, New 
Mexico, were without water for 4 hours February 9 due to a leak in the village’s main 
transmission line. A Hatch public works official estimated that about 800 gallons of 
water was lost before the leak was found. 

Source: http://www.lcsun-news.com/las cruces-news/ci 27491234/water-main-leak- 
will-force-water-shutoff-hatch 
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Healthcare and Public Health Sector 

21. February 9, Reuters - (International) California confirms 107 cases of measles, 39 
from Disneyland outbreak. California health officials reported that 107 cases of 
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measles were confirmed in the State February 9 and 39 of them linked to a December 
2014 outbreak that began in Disneyland. More than 3 dozen additional cases of the 
disease have been reported in 19 other States and in Mexico. 

Source: http://www.msn.com/en-us/news/us/california-confirms-107-cases-of-measles- 
39-from-disneyland-outbreak/ar-AA9bOHN 

22. February 9, Alaska Dispatch News - (Alaska) All residents evacuated as fire breaks 
out in Wasilla assisted -living home. Sixteen residents from the Northern Comfort 
Assisted Living facility in Wasilla were evacuated and moved to temporary residences 
due to a fire that broke out on the second floor of the building February 9. Authorities 
are investigating the cause of the fire. 

Source: http://www.adn.com/article/20150209/all-residents-evacuated-fire-breaks-out- 
wasilla-assisted-living-home 
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Government Facilities Sector 

23. February 10, Albany Times Union - (New York) Cohoes City Hall slammed by 
broken steam and water pipes. Cohoes City Hall in New York was closed for repairs 
February 9 after a water main burst and flooded the basement, and steam pipes to the 
boiler blew, cutting off heat. City officials reported that there was no estimate on total 
damages. 

Source: http://www.timesunion.com/news/article/Cohoes-Citv-Hall-closed-bv- 
flooding-6070979.php 

24. February 9, Honolulu Star-Advertiser - (Hawaii) Winds rip portion of Keolu 
Elementary’s roof; school closed Tuesday. Keolu Elementary School in Kailua was 
closed February 10 after strong winds ripped portions of the roof off February 9. 

School officials worked to repair the damage and ensure the campus is safe before 
resuming classes. 

Source: 

http://www.staradvertiser.com/news/breaking/20150209 Winds rip portion of Keolu 
Elementarys roof school closed Tuesday.html?id=29 13460 11 

T Return to top i 

Emergency Services Sector 

25. February 9, KVUE 24 Austin - (Texas) Sniper kills man who shot at police 
helicopter. Police shot and killed a man February 8 who fired multiple rounds at an 
Austin Police Department helicopter in a southwest Austin neighborhood after 
responding to reports of a man who was shooting at streetlights in the neighborhood. 
Source: http://www.wcnc.com/storv/news/crime/2015/02/09/sniper-kills-rnan-who- 
shot-at-police-helicopter/23 1 1 805 1/ 

26. February 9, Jackson Clarion-Ledger - (Mississippi) Another inmate pleads guilty to 
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murder in Adams Co. prison riot. A second inmate pleaded guilty February 9 to 
murder charges in connection to a May 2012 Adams County Correctional Facility riot 
that left a corrections officer dead. The riot at the Mississippi facility involved at least 
19 inmates who aided in assaulting several correctional officers and taking them 
hostage. 

Source: http://www.clarionledger.com/story/news/2015/02/09/another-inmate-pleads- 
guilty-to-murder-in-adams-co-prison-riot/23 143 107/ 

27. February 9, WSOC 9 Charlotte - (North Carolina) Sheriff: Guns, SWAT gear stolen 
from deputy’s cruiser. Authorities are searching for thieves February 9 who’ve stolen 
body armor, tactical weapons, and bullets from an unmarked Lincoln County sergeant’s 
patrol car while it was parked at his home in Catawba County. 

Source: http://www.wsoctv.com/news/news/local/deputies-guns-swat-gear-stolen- 
lincoln-co-deputys-/ni7LL/ 

For another story, see item 19 
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Information Technology Sector 

28. February 10, Softpedia - (International) About 40,000 MongoDB databases found 
open online. Three Saarland University cyber-security students reported security 
vulnerabilities in MongoDB’ s database configuration, including servers with no access 
control mechanisms that could potentially allow access outside the backend and expose 
the information of millions of customer to unauthorized parties. An initial scan found 
nearly 40,000 databases that were open, prompting the researchers to submit their 
findings to MongoDB maintainers for integration into revised security instructions for 
users. 

Source: http://news.softpedia.com/news/About-40-00Q-MongoDB-Databases-Found- 
Open-Online-472747.shtml 

29. February 10, Securityweek - (International) Researcher publishes 10 million 
usernames and passwords. A researcher released 10 million username/password 
combinations that he collected over the years in an attempt to advance research and 
make authentication more secure. The researcher asserted that most combinations were 
dated and had been scrubbed of all identifying and compromising information. 

Source: http://www.securitvweek.com/researcher-publishes-10-million-usernames-and- 
passwords 

30. February 9, Securityweek - (International) Box Sync for Mac exposed sensitive 
information: Researcher. Box Sync for Mac released version 4.0.6035 to fix a 
security issue discovered in January that exposed Python files containing sensitive data 
such as application program interface (API) keys, internal user IDs, passwords, and 
URLs. Box Sync representatives asserted that customer data was never at risk. 

Source: http://www.securitvweek.com/box-svnc-mac-exposed-sensitive-information- 
researcher 



-8 - 



3 1 . February 9, Securityweek - (International) LG fixes authentication bypass 

vulnerability in on-screen phone app. LG released On-Screen Phone application 
update 4.3.010 to fix a vulnerability discovered by Search-Lab researchers in 
September 2014 that allowed attackers to possibly bypass authentication and take 
control of users’ smartphones without their knowledge through a connection between 
the mobile device and the computer conducted via USB cable, Wi-Fi, or Bluetooth. 
Source: http://www.securitvweek.com/lg-fixes-authentication-bvpass-vulnerabilitv- 
screen-phone-app 

For another story, see item 1 



Internet Alert Dashboard 



To report cyber infrastructure incidents or to request information, please contact US-CERT at soc@us-cert.gov or 
visit their Web site: http://www.us-cert.gov 

Information on IT information sharing and analysis can be found at the IT IS AC (Information Sharing and 
Analysis Center) Web site: http://www.it-isac.org 
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Communications Sector 

Nothing to report 
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Commercial Facilities Sector 

32. February 10, KMOV 4 St. Louis - (Missouri) Red Cross assists 23 individuals after 
late night apartment complex fire. A fire that broke out February 9 in a basement 
storage unit of a Shrewsbury apartment complex spread throughout the structure and 
displaced 23 residents. Nobody was injured during the fire and a temporary warming 
shelter was set up for displaces residents. 

Source: http://www.kmov.com/news/local/Fire-at-Shrewsburv-apartment-complex- 
displaces-at-least-12-families-29 1351 131.html 

33. February 9, Asheville Citizen-Times - (North Carolina) Three charged in pipe bomb, 
arson plot. The Buncombe County Sheriffs Office reported February 9 the arrest of 
three individuals who were charged with allegedly igniting a pipe bomb and fuel at The 
Red Oak Crossing store in Weaverville November 8 in an attempt to cause an 
explosion that distracted first responders from a planned armed robbery at a nearby 
McDonald’s restaurant. 

Source: http://www.citizen-times.com/story/news/crime/2015/02/09/three-charged- 
pipe -bomb-arson-plot/23 1 37809/ 

34. February 9, Grand Forks Herald - (North Dakota) Fire sends 1 man to hospital, 
displaces residents of downtown Grand Forks apartment building. A fire at the 
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Ryan House apartment building in Grand Forks February 9 prompted a several hour 
evacuation of 50 residents and left 14 residents displaced. Two individuals were treated 
for injuries sustained during the fire that remains under investigation. 

Source: http://www.grandforksherald.com/news/local/3675077-update-fire-sends-l- 
man-hospital-displaces-residents-downtown-grand-forks 

35. February 9, Associated Press - (West Virginia) Walmart in Martinsburg evacuated 
after 2 fires set. A Walmart store in Martinsburg was evacuated and closed February 8 
due to two arson fires that were intentionally set inside the business. The incident 
remains under investigation. 

Source: http://www.bdtonline.com/news/walmart-in-martinsburg-evacuated-after-fires- 
set/article 044ble22-b066-l Ie4-95f9-6bea0ba8da52.html 



For another story, see item 4 
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Dams Sector 



Nothing to report 
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summary of open-source published information concerning significant critical infrastructure issues. The DHS Daily 
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Daily Report Team at (703) 942-8590 
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Contact DHS 

To report physical infrastructure incidents or to request information, please contact the National Infrastructure 
Coordinating Center at nicc@hq.dhs.gov or (202) 282-9201. 

To report cyber infrastructure incidents or to request information, please contact US -CERT at soc@us-cert.gov or visit 
their Web page at www.us-cert.gov . 

Department of Homeland Security Disclaimer 

The DHS Daily Open Source Infrastructure Report is a non-commercial publication intended to educate and inform 
personnel engaged in infrastructure protection. Further reproduction or redistribution is subject to original copyright 
restrictions. DHS provides no warranty of ownership of the copyright, or accuracy with respect to the original source 
material. 
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